Remix.run Logo
vladvasiliu 2 hours ago

You can have automatic unlock with tpm2, with or without a pin, in addition to passphrase, file, fido2, pkcs#11 cert, or whatever else is supported by luks.

I've been using this for a few years now, and never had an issue.

https://wiki.archlinux.org/title/Systemd-cryptenroll

> Imagine a motherboard failure and boom there goes my entire disk.

You can also set a long-ass key in addition to the other methods, and back it up somewhere safe. It works the same as bitlocker: you have key which can decrypt the drive without external help from a TPM in case something goes wrong.